Skip to main content
Released

FME Server Enforce password renewal after a certain period of time

Related products:FME Form
  • May 17, 2018
  • 4 replies
  • 77 views

mygis
Supporter
Forum|alt.badge.img+15

Give the option to provide the capability to enforce password renewal for users in FME Server.


This post is closed to further activity.
It may be an old question, an answered question, an implemented idea, or a notification-only post.
Please check post dates before relying on any information in a question or answer.
For follow-up or related questions, please post a new question or idea.
If there is a genuine update to be made, please contact us and request that the post is reopened.

4 replies

rylanatsafe
Safer
Forum|alt.badge.img+14
  • Safer
  • September 24, 2019

We would like to gather some feedback from those who have expressed interest in this idea.

1. This would be a configurable option, that can be enabled by any FME Server administrator in the web interface after an installation is complete. Would this be a problem for any of your deployment workflows?

2. What types of configurable options are required for setting the "time length" before a password is marked expired? Would setting an integer value for either days, weeks, months, or years be acceptable?

3. Given that a user's password has expired, should that user be able to access any functionality (including REST API endpoints)? If "yes", please be specific.

4. Given that a user's password has expired, that user must change their password by accessing the web interface and logging in with old credentials – where they would be prompted with a web form to enter a new password. Is this acceptable, or would you suggest changes to this workflow?

5. Given that a user's password has expired, should that user have any of their API Tokens disabled? Note that this would affect FME Server Apps as well.

 

This feature would only apply to local user accounts on FME Server, and would not affect any Active Directory accounts that have been imported.

Any feedback is greatly appreciated! Please do not feel obligated to answer or comment on every item above, and let us know if you have any other criteria to add.


rylanatsafe
Safer
Forum|alt.badge.img+14
  • Safer
  • November 25, 2019

For the first iteration / feature release, please see below for the implementation choices that were made...

1. This is a configurable option, that can be enabled by any FME Server administrator in the web interface after an installation is complete.

2. Users can set the number of days before a password is marked expired; this is across all FME Server User Accounts – though does not affect Active Directory.

3. Given that a user's password has expired, that user will not be able to access any FME Server functionality (including REST API endpoints) until they reset their password in the Web Interface.

4. Given that a user's password has expired, that user must change their password by accessing the Web Interface and logging in with old credentials – where they would be prompted with a web form to enter a new password

5. Given that a user's password has expired, their API Tokens are not disabled.


rylanatsafe
Safer
Forum|alt.badge.img+14
  • Safer
  • November 25, 2019

This is now available in FME Server 2020.0 betas! Please use Build 20124 or newer.


rylanatsafe
Safer
Forum|alt.badge.img+14
  • Safer
  • March 13, 2020

We are excited to announce that this feature is available in FME Server 2020.0! Check out this article for information on other new and updated features.